← nRiZE Co., Ltd.

2023 Wippy (nRiZE) — identity-verification flaw; 736 dating-app profiles (PIPC fine Aug 2026)

2023 736 records affected Share on X

Data compromised

Nicknames, profile photos, dates of birth, education, occupation, height, blood type, and other profile fields for 736 accounts

Technical writeup

Verified regulator enforcement — disclosed August 31, 2026. South Korea’s PIPC fined nRiZE, operator of the Wippy dating app, ₩118.44 million plus a ₩3.6 million administrative penalty after a March 2023 incident in which an attacker abused an identity-verification weakness to exfiltrate profile data from 736 accounts (nicknames, photos, dates of birth, education, occupation, height, blood type, and related fields). The fine was announced alongside the GS Retail and SK Telecom ifland actions in the same PIPC plenary batch. recordsAffected 736 from regulator attestation; companyConfirmed true.

Root cause

Hacker exploited vulnerability in Wippy identity-verification system (March 2023) per PIPC August 2026 enforcement action

References